Visit NES for Apache Struts Home Page
Apache Struts Forward Compatibility 1.3 1.4.x Release Notes
5 versions
Comprehensive release notes and changelog for Apache Struts Forward Compatibility 1.3 1.4.x, including security patches, bug fixes, and feature updates across all supported versions.
December 2025
September 2025
August 2025
1.4.2
Released Aug 25, 2025 Full Version:
1.3.10-struts-1.4.2
Notes
- updates to
struts-facesto fully support Jakarta EE 9
1.4.1
Released Aug 4, 2025 Full Version:
1.3.10-struts-1.4.1
Bug Fixes
This release patches the following:
- CVE-2025-54656: Improper Output Neutralization for Logs Vulnerability
- CVE-2025-48976: FileUpload DoS via part headers
- CVE-2025-48734: Improper Access Control vulnerability
- Dependency upgrade of beanutils to
1.11.0or override tones-v1.7.4addresses this vulnerability.
- Dependency upgrade of beanutils to
Dependency Upgrades
- commons-beanutils:commons-beanutils 1.9.4 -> 1.11.0
- org.apache.commons:commons-fileupload2-core 2.0.0-M1 -> 2.0.0-M4
- org.apache.commons:commons-fileupload2-jakarta 2.0.0-M1 -> commons-fileupload2-jakarta-servlet5 2.0.0-M4
June 2025
1.4.0
Released Jun 25, 2025 Full Version:
1.3.10-struts-1.4.0
Notes
- This release originates from NES for Apache Struts 1.3.x and is designed to be compatible with Jakarta EE environments.
Dependency Upgrades
- commons-fileupload 2.0.0-M1
- Jakarta EE 9 compatibility:
- jakarta.faces-api 3.0.0
- jakarta.servlet-api 5.0.0
- jakarta.servlet.jsp-api 3.0.0
- jakarta.el-api 4.0.0
Full Version:
1.3.10-struts-1.4.0
Stay in the loop
~/herodevs-spring-framework-support
herodevs@nes:open-source$ ./display-support-info.sh